2026-07-11
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- threat intel
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Version 8.14.0 of the jscrambler npm package contained a malicious preinstall hook that silently deployed a Rust-based infostealer on Windows, macOS, and Linux systems during installation. The package required no manual import or command line invocation to execute the malware. Socket security detected the compromised release approximately six minutes after its publication on July 11, 2026.
Why it matters: Developers and organizations using jscrambler are at immediate risk of information theft from their build environments; this requires urgent action to audit installations, identify compromised systems, and upgrade to a patched version.
- threat intel
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Researchers disclosed sustained cyber espionage targeting multiple Pakistani law‑enforcement agencies, attributing the activity to suspected China‑ and India‑aligned threat actors. The campaign, observed from February 2024 through April 2026, compromised Balochistan Police servers that host web applications for police and citizen records. Investigators noted that the compromised assets included systems handling criminal and personal data.
Why it matters: Pakistani law-enforcement agencies, particularly Balochistan Police, face exposure of police and citizen data via compromised web-application servers and should audit and harden those portals.
- threat intel
Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Threat actors are using ghost accounts on GitHub to conduct large-scale reconnaissance campaigns targeting organizations, their repositories, and members. These fake accounts abuse the GitHub application programming interface (API) to automate the mapping and discovery of organizational structures and resources.
Why it matters: Development teams and organizations hosting code on GitHub should audit their access logs and consider restricting API token permissions, as this reconnaissance typically precedes targeted attacks or supply chain compromises.
- threat intel
Australia warns of global campaign targeting vulnerable CMS platforms
The Australian Cyber Security Centre (ACSC) alerted organizations to an active global campaign exploiting vulnerabilities in content management systems and their plugins. The campaign targets organizations running outdated or unpatched CMS deployments across multiple sectors.
Why it matters: Organizations running CMS platforms face immediate compromise risk if running vulnerable versions; practitioners should audit deployed CMS instances, apply patches promptly, and monitor for signs of exploitation.
- ransomware
Ransomware negotiator who conspired with BlackCat threat actors sentenced to 70 months in prison
A former ransomware negotiator employed by DigitalMint has been sentenced to 70 months in prison for conspiring with BlackCat threat actors. The negotiator provided BlackCat with inside information about victims' defense strategies, enabling the group to extort the companies he was hired to protect. This represents the third co-conspirator in the scheme to face sentencing.
Why it matters: Negotiators and insiders with knowledge of victim response plans pose a critical supply chain risk; organizations must implement access controls and monitoring for personnel with visibility into crisis strategies and victim defenses.
- breaches incidents
TikTok class action alleges data breach affected 2.4B users
A California resident filed a class action lawsuit against TikTok on June 11, 2026, claiming a data breach exposed personal data of more than 2.4 billion users globally. The complaint alleges TikTok stored unencrypted data and failed to implement basic security measures.
Why it matters: TikTok users and organizations handling user data face exposure risk; practitioners should monitor the litigation outcome and assess whether TikTok's security posture requires changes to data handling policies.
- ai security
AI Found a Root Bug in Linux That Everyone Missed for 15 Years
An artificial intelligence system discovered a longstanding vulnerability in the Linux kernel that remained undetected for 15 years. The article also covers Pentagon efforts to recruit non-professionals into offensive cyber operations and a law enforcement incident involving a Flock license plate reader misidentification.
Why it matters: Linux maintainers and downstream distributors should assess whether this vulnerability affects their kernels and prioritize patches; organizations relying on Flock data should review potential false-positive incidents and validate their processes.
- vulnerabilities
Wireshark 4.6.7 Released
Wireshark 4.6.7 was released with fixes for 12 vulnerabilities and 16 bugs. The update addresses security issues and stability improvements across the packet analysis tool.
Why it matters: Network administrators and security analysts using Wireshark should apply this update to patch known vulnerabilities and reduce exposure to potential exploitation.
- ai security
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
Researchers demonstrated a prompt injection attack dubbed Ghostcommit that embeds malicious instructions in PNG images to manipulate artificial intelligence (AI) code reviewers and agents. The technique bypassed AI code review tools CodeRabbit and Bugbot, then tricked a coding agent into extracting secrets from a repository's environment file and encoding them as numbers within source code.
Why it matters: Development teams using AI-assisted code review and autonomous agents face risk of secret exfiltration through image-based prompt injection; practitioners should review how their AI tools handle image inputs and restrict agent access to sensitive environment files.
- breaches incidents
US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals
A CISA contractor employee accidentally uploaded exposed passwords to a publicly accessible GitHub repository, which a GitGuardian researcher discovered and reported in May. The incident revealed that CISA had to develop its incident response procedures in real time during the event rather than having them prepared in advance.
Why it matters: CISA and federal agencies relying on its contractors face credential exposure and operational risk when incident response playbooks are absent, requiring practitioners to ensure their own organizations have pre-built response procedures in place.
- vulnerabilitiesCVE-2024-27822CVE-2026-41264
Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit
Metasploit released new exploit modules for three vulnerabilities: FlowiseAI CSV Agent (CVE-2026-41264), an unauthenticated remote code execution flaw allowing attackers to upload malicious CSV files; macOS PackageKit (CVE-2024-27822), a privilege escalation vulnerability in ZSH environment handling; and Apache .htaccess persistence for Linux systems. The update also includes enhancements to FTP fingerprinting, library reloading, MCP Server tools, and certificate tracing functionality.
Why it matters: Security practitioners should review patches for Flowise versions 1.3.0 through 3.0.13 and macOS versions 14.4, 13.6.6, 12.7.4, and 11 or earlier, as these vulnerabilities enable unauthenticated remote code execution and local privilege escalation respectively.